We take the security of Navixy — and of the systems our customers run on it — seriously. Thank you for helping keep the platform and its users safe.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report privately through either channel:
- GitHub private advisory — on the affected repository, open the Security tab and use “Report a vulnerability.” See GitHub's guide on privately reporting a security vulnerability.
- Email — security@navixy.com
Please include, where you can:
- a description of the issue and the affected component, endpoint, or repository;
- steps to reproduce, or a proof of concept;
- the impact you expect; and
- any suggested remediation.
- We aim to acknowledge your report within two business days.
- We will keep you updated as we investigate and work on a fix.
- We ask for a reasonable opportunity to remediate before public disclosure, and we're happy to coordinate timing with you.
- With your permission, we're glad to credit you once the issue is resolved.
This policy covers the source code in the Navixy GitHub organization. For
issues in the hosted Navixy platform or your account data, contact your
Navixy account manager or regional support channel so we can route it to the
right team quickly.